Even with OT network visibility, critical infrastructure operators struggle with legacy equipment

Large critical infrastructure operators run seven separate security tools on average, and most still cannot see every asset on their operational technology (OT) networks. That is the picture from a Palo Alto Networks survey of more than 1,600 security and operations leaders.

OT network visibility

Old equipment stays on the network

Legacy OT is the most common visibility problem, named by 52 percent of respondents. Another 42 percent call legacy equipment that cannot be patched their biggest cybersecurity risk. Even among respondents who say they see everything, 49 percent still list legacy OT as a challenge. Knowing a machine is there does not update its software.

“Cybersecurity in critical infrastructure today is at a dangerous point where we’ve connected decades-old OT to modern networks faster than we’ve updated the security models needed to protect them,” said a VP of IT at a US manufacturer.

Buying more tools did not fix it

Fifty-nine percent of respondents say the tools make operations more complicated, and 56 percent report higher operating costs. Just over half still sort alerts with a standard severity score or by hand. If your team has added a tool every time a new gap turned up, this is the pattern the survey describes.

Breaches were common last year

Fifty-nine percent had a significant security breach in the past twelve months, and one in five was hit more than once. Half of respondents list safety concerns among the impacts of incidents, and unplanned downtime costs a mean of $288,563 per hour.

Containment is getting faster from a low start. Fifteen percent now contain incidents in minutes through automation, up from 10 percent a year ago. Fifty-one percent want to be there within the next twelve months. Fifteen percent are there today.

AI is the next worry

Ninety-five percent are concerned about attacks powered by what the survey calls Frontier AI, and 91 percent expect AI-driven security tools to help defend against them. Few have much AI in place yet. Only 19 percent use it across four or more operational areas, and those areas include process optimization and predictive maintenance, so the figure is not limited to security.

IT and OT teams still work apart

Seventy-four percent have not integrated their IT and OT security operations. Among them, 44 percent point to incompatible technology and 44 percent to differing priorities between the two teams.

Automated alert correlation tops the wish list for closing the divide. Fifty-two percent of respondents picked it as the thing that would most speed IT and OT convergence over the next two years.

Webinar: Closing the accountability gap in AI-assisted delivery

Don't miss